{"schemaVersion":"developer.reits.tech/aws-validation-identity/v1","status":"T02_REPOSITORY_IMPLEMENTED_LIVE_IDENTITY_REQUIRED","evaluatedAt":"2026-07-24T07:38:32Z","program":{"acceptedKnives":4,"totalKnives":36,"currentOrdinal":5,"currentKnife":"D05","remainingIncludingCurrent":32,"remainingAfterCurrentAcceptance":31},"task":{"id":"D05-T02","title":"Independent AWS validation identity","repositoryImplementationComplete":true,"cloudOwnerProvisioningRequired":true,"liveIdentityObserved":false,"awsTemplateValidated":false,"productionAccepted":false,"nextTask":"D05-T03","nextTaskBlocked":true,"nextTaskTitle":"Approve two isolated Linux runner costs"},"observation":{"workspace":"developer-portal-local","awsCli":"ABSENT","profilesDiscovered":0,"awsEnvironmentCredentialVariables":0,"callerIdentityExecuted":false,"currentPrincipal":null,"priorPrincipal":"iam-user/cc","priorObservation":"2026-07-20T11:40:44Z","priorObservationFreshness":"STALE_SUPERSEDED","productionHostAwsCli":"PRESENT_INELIGIBLE_NOT_INVOKED","productionHostEligible":false,"reason":"No AWS CLI or AWS credential environment is present in the current workspace. The shared production EC2 host is never an eligible validation identity source."},"roleContract":{"roleName":"reits-cloudformation-validator","sessionType":"ASSUMED_ROLE_TEMPORARY","maximumSessionSeconds":3600,"trustedPrincipal":"CLOUD_OWNER_SUPPLIED_EXACT_IAM_PRINCIPAL_ARN","externalIdRequired":true,"sessionNamePattern":"reits-validator-*","permissionsBoundaryRequired":true,"allowedActions":["cloudformation:ValidateTemplate","sts:GetCallerIdentity"],"explicitDenyEveryOtherAction":true,"deploymentActionsAllowed":false,"longLivedAccessKeysAllowed":false,"instanceMetadataCredentialsAllowed":false,"containerCredentialsAllowed":false,"targetTemplate":"ops/gitea-runner/cloudformation.yaml","targetRegion":"ap-southeast-2"},"verificationFlow":[{"ordinal":1,"id":"OWNER_INSTALL","owner":"Cloud Account Owner","state":"OWNER_ACTION_REQUIRED","detail":"Install the role template with an exact trusted IAM principal and out-of-band external ID."},{"ordinal":2,"id":"FEDERATE","owner":"Independent Validator","state":"BLOCKED_IDENTITY_ABSENT","detail":"Use an explicit AWS CLI role profile backed by federated or otherwise temporary source credentials."},{"ordinal":3,"id":"IDENTIFY","owner":"Validation Script","state":"BLOCKED_AWS_CLI_ABSENT","detail":"Call STS GetCallerIdentity and require the exact assumed-role ARN and expected account."},{"ordinal":4,"id":"VALIDATE","owner":"AWS CloudFormation","state":"BLOCKED_IDENTITY_ABSENT","detail":"Validate only the pinned runner template body in ap-southeast-2; do not create a change set or stack."},{"ordinal":5,"id":"PROVE_DENY","owner":"Validation Script","state":"BLOCKED_IDENTITY_ABSENT","detail":"Require a read-only EC2 DescribeInstances probe to fail with AccessDenied, proving the role is not a general cloud identity."},{"ordinal":6,"id":"SEAL_RECEIPT","owner":"Independent Validator","state":"BLOCKED_PREDECESSOR","detail":"Write a secret-free local receipt binding account, principal, template SHA-256, region and validation response."}],"repositoryEvidence":{"roleTemplate":"ops/aws-validation-identity/cloudformation.yaml","permissionsPolicy":"ops/aws-validation-identity/validator-policy.json","profileExample":"ops/aws-validation-identity/config.example","liveVerifier":"ops/aws-validation-identity/validate-template.sh","runbook":"ops/aws-validation-identity/README.md","staticVerification":"npm run aws-validation-identity:verify"},"liveEvidence":{"roleCreated":false,"assumedRoleObserved":false,"expectedAccountMatched":false,"validateTemplateSucceeded":false,"denyProbeSucceeded":false,"receiptObserved":false,"paidResourcesCreated":0,"productionChangesAuthorized":0,"gateG01Satisfied":false},"invariants":{"validationIdentityDistinctFromDeploymentIdentity":true,"validationIdentityDistinctFromProductionHostIdentity":true,"staticAccessKeysAccepted":false,"instanceRoleCredentialsAccepted":false,"arbitraryTemplateAccepted":false,"cloudFormationMutationAllowed":false,"runnerProvisioningAllowed":false,"d05Accepted":false,"programAdvanced":false},"officialReferences":{"iamBestPractices":"https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html","cliRoleProfiles":"https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-role.html","validateTemplate":"https://docs.aws.amazon.com/AWSCloudFormation/latest/APIReference/API_ValidateTemplate.html","getCallerIdentity":"https://docs.aws.amazon.com/STS/latest/APIReference/API_GetCallerIdentity.html","notAction":"https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_elements_notaction.html"},"boundary":"D05-T02 repository engineering is complete, but the Cloud Account Owner has not installed the role and no independent assumed-role session or AWS ValidateTemplate receipt exists. D05-T03 remains blocked, G01 remains false, D05 remains 0/11 and implementation remains 4/36."}